.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by [removed] at 13:20:23 on 2011-07-06
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.285 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\svchost.exe -k HPService
C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AppLifeUpdateService2\kjsausvc.exe
C:\Program Files\DISC\DiscGui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\xra.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
svchost.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uInternet Settings,ProxyOverride = <local>;*.local
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [2163372474] c:\documents and settings\hp_administrator\local settings\application data\xra.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE
mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe
mRun: [DISCover] c:\program files\disc\DISCover.exe
mRun: [DiscUpdateManager] c:\program files\disc\DiscUpdateMgr.exe
mRun: [PCDrProfiler]
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [StatusClient] c:\program files\hewlett-packard\toolbox2.0\apache tomcat 4.0\webapps\toolbox\statusclient\StatusClient.exe /auto
mRun: [TomcatStartup] c:\program files\hewlett-packard\toolbox2.0\hpbpsttp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Verizon_McciTrayApp] "c:\program files\verizon\McciTrayApp.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ThinkecoTray] c:\program files\thinkeco\Thinkeco.Tray.exe
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wddmst~1.lnk - c:\program files\western digital\wd smartware\wd drive manager\WDDMStatus.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
Trusted Zone: intuit.com\ttlc
Trusted Zone: trymedia.com
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxps://h50203.www5.hp.com/HPISWeb/Cust ... anager.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shoc ... wflash.cab
DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} - hxxp://update.hpphoto.com/download/HPSWUpdate.ocx
TCP: DhcpNameServer = 192.168.1.1 [removed]
TCP: Interfaces\{85761875-79C4-467B-A942-A4CEC9B955FC} : DhcpNameServer = 192.168.1.1 [removed]
TCP: Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D} : DhcpNameServer = [removed] [removed] [removed] [removed]
Notify: AtiExtEvent - Ati2evxx.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl9e2cf0b5;MpKsl9e2cf0b5;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\MpKsl9e2cf0b5.sys [2011-7-6 28752]
R1 MpKslf32c8340;MpKslf32c8340;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\MpKslf32c8340.sys [2011-7-4 28752]
R2 IHA_MessageCenter;IHA_MessageCenter;c:\program files\verizon\iha_messagecenter\bin\Verizon_IHAMessageCenter.exe [2010-10-13 98304]
R2 KjsUpdateService2;AppLife Update Service 2.0;c:\program files\common files\applifeupdateservice2\kjsausvc.exe [2011-3-8 12800]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-6 99328]
R2 WDDMService;WDDMService;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2011-3-9 238592]
R2 WDFME;WD File Management Engine;c:\program files\western digital\wd smartware\front parlor\wdfme\WDFME.exe [2011-3-9 1060864]
R2 WDSC;WD File Management Shadow Engine;c:\program files\western digital\wd smartware\front parlor\WDSC.exe [2011-3-9 484352]
S1 MpKsl05d807cb;MpKsl05d807cb;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8dbf0d4b-7a59-4a0f-b479-64665b01ebad}\mpksl05d807cb.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8dbf0d4b-7a59-4a0f-b479-64665b01ebad}\MpKsl05d807cb.sys [?]
S1 MpKsl1cfde53a;MpKsl1cfde53a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\mpksl1cfde53a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\MpKsl1cfde53a.sys [?]
S1 MpKsl41b6522a;MpKsl41b6522a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8dbf0d4b-7a59-4a0f-b479-64665b01ebad}\mpksl41b6522a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8dbf0d4b-7a59-4a0f-b479-64665b01ebad}\MpKsl41b6522a.sys [?]
S1 MpKsl61898b40;MpKsl61898b40;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\mpksl61898b40.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\MpKsl61898b40.sys [?]
S1 MpKsl9d6e38de;MpKsl9d6e38de;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{14e363de-8d35-4092-8fa7-36b468d1b59b}\mpksl9d6e38de.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{14e363de-8d35-4092-8fa7-36b468d1b59b}\MpKsl9d6e38de.sys [?]
S1 MpKslb3d1330b;MpKslb3d1330b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{10c69094-d2bc-468e-ad4e-b14fe1c5365f}\mpkslb3d1330b.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{10c69094-d2bc-468e-ad4e-b14fe1c5365f}\MpKslb3d1330b.sys [?]
S1 MpKslb5a07ffb;MpKslb5a07ffb;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\mpkslb5a07ffb.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\MpKslb5a07ffb.sys [?]
S1 MpKslb78b15a1;MpKslb78b15a1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{10c69094-d2bc-468e-ad4e-b14fe1c5365f}\mpkslb78b15a1.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{10c69094-d2bc-468e-ad4e-b14fe1c5365f}\MpKslb78b15a1.sys [?]
S1 MpKslc83e9ebf;MpKslc83e9ebf;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4539468b-f127-4e2f-b93b-79519c21b78a}\mpkslc83e9ebf.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4539468b-f127-4e2f-b93b-79519c21b78a}\MpKslc83e9ebf.sys [?]
S1 MpKsld1895537;MpKsld1895537;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\mpksld1895537.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\MpKsld1895537.sys [?]
S1 MpKsle905f07a;MpKsle905f07a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dae9692b-afd7-461d-8a4f-21a708cd4fef}\mpksle905f07a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dae9692b-afd7-461d-8a4f-21a708cd4fef}\MpKsle905f07a.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 ThinkEco Modlet Service;ThinkEco Modlet Service;c:\program files\thinkeco\thinkeco.service.exe --> c:\program files\thinkeco\ThinkEco.Service.exe [?]
.
=============== Created Last 30 ================
.
2011-07-06 14:55:40 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\MpKsl9e2cf0b5.sys
2011-07-04 20:29:40 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\MpKslf32c8340.sys
2011-07-03 15:09:08 331776 ----a-w- c:\documents and settings\hp_administrator\local settings\application data\xra.exe
2011-07-03 05:54:28 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\mpengine.dll
2011-06-28 07:10:21 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-06-10 21:44:37 -------- d-----w- C:\ThinkEco
2011-06-10 21:44:37 -------- d-----w- c:\program files\common files\AppLifeUpdateService2
2011-06-10 21:44:30 -------- d-----w- c:\documents and settings\hp_administrator\application data\ThinkEco
2011-06-10 21:44:23 -------- d-----w- c:\documents and settings\all users\application data\ThinkEco
2011-06-10 21:33:49 73032 ----a-w- c:\windows\system32\drivers\ftser2k.sys
2011-06-10 21:33:49 67400 ----a-w- c:\windows\system32\ftcserco.dll
2011-06-10 21:33:49 52552 ----a-w- c:\windows\system32\ftserui2.dll
2011-06-10 21:33:46 60104 ----a-w- c:\windows\system32\drivers\ftdibus.sys
2011-06-10 21:33:46 198464 ----a-w- c:\windows\system32\ftd2xx.dll
2011-06-10 21:33:46 197952 ----a-w- c:\windows\system32\FTLang.dll
2011-06-10 21:33:46 105288 ----a-w- c:\windows\system32\ftbusui.dll
.
==================== Find3M ====================
.
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-29 14:57:06 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-04-29 14:57:05 410984 ----a-w- c:\windows\system32\deploytk.dll
2011-04-25 15:51:58 832512 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 15:51:57 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-04-25 15:51:57 1830912 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 15:51:57 17408 ----a-w- c:\windows\system32\corpol.dll
2011-04-25 12:01:21 389120 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
============= FINISH: 13:26:42.21 ===============
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by [removed] at 13:20:23 on 2011-07-06
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.285 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\svchost.exe -k HPService
C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AppLifeUpdateService2\kjsausvc.exe
C:\Program Files\DISC\DiscGui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\xra.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
svchost.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uInternet Settings,ProxyOverride = <local>;*.local
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [2163372474] c:\documents and settings\hp_administrator\local settings\application data\xra.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE
mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe
mRun: [DISCover] c:\program files\disc\DISCover.exe
mRun: [DiscUpdateManager] c:\program files\disc\DiscUpdateMgr.exe
mRun: [PCDrProfiler]
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [StatusClient] c:\program files\hewlett-packard\toolbox2.0\apache tomcat 4.0\webapps\toolbox\statusclient\StatusClient.exe /auto
mRun: [TomcatStartup] c:\program files\hewlett-packard\toolbox2.0\hpbpsttp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Verizon_McciTrayApp] "c:\program files\verizon\McciTrayApp.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ThinkecoTray] c:\program files\thinkeco\Thinkeco.Tray.exe
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wddmst~1.lnk - c:\program files\western digital\wd smartware\wd drive manager\WDDMStatus.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
Trusted Zone: intuit.com\ttlc
Trusted Zone: trymedia.com
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxps://h50203.www5.hp.com/HPISWeb/Cust ... anager.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shoc ... wflash.cab
DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} - hxxp://update.hpphoto.com/download/HPSWUpdate.ocx
TCP: DhcpNameServer = 192.168.1.1 [removed]
TCP: Interfaces\{85761875-79C4-467B-A942-A4CEC9B955FC} : DhcpNameServer = 192.168.1.1 [removed]
TCP: Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D} : DhcpNameServer = [removed] [removed] [removed] [removed]
Notify: AtiExtEvent - Ati2evxx.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl9e2cf0b5;MpKsl9e2cf0b5;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\MpKsl9e2cf0b5.sys [2011-7-6 28752]
R1 MpKslf32c8340;MpKslf32c8340;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\MpKslf32c8340.sys [2011-7-4 28752]
R2 IHA_MessageCenter;IHA_MessageCenter;c:\program files\verizon\iha_messagecenter\bin\Verizon_IHAMessageCenter.exe [2010-10-13 98304]
R2 KjsUpdateService2;AppLife Update Service 2.0;c:\program files\common files\applifeupdateservice2\kjsausvc.exe [2011-3-8 12800]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-6 99328]
R2 WDDMService;WDDMService;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2011-3-9 238592]
R2 WDFME;WD File Management Engine;c:\program files\western digital\wd smartware\front parlor\wdfme\WDFME.exe [2011-3-9 1060864]
R2 WDSC;WD File Management Shadow Engine;c:\program files\western digital\wd smartware\front parlor\WDSC.exe [2011-3-9 484352]
S1 MpKsl05d807cb;MpKsl05d807cb;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8dbf0d4b-7a59-4a0f-b479-64665b01ebad}\mpksl05d807cb.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8dbf0d4b-7a59-4a0f-b479-64665b01ebad}\MpKsl05d807cb.sys [?]
S1 MpKsl1cfde53a;MpKsl1cfde53a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\mpksl1cfde53a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\MpKsl1cfde53a.sys [?]
S1 MpKsl41b6522a;MpKsl41b6522a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8dbf0d4b-7a59-4a0f-b479-64665b01ebad}\mpksl41b6522a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8dbf0d4b-7a59-4a0f-b479-64665b01ebad}\MpKsl41b6522a.sys [?]
S1 MpKsl61898b40;MpKsl61898b40;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\mpksl61898b40.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\MpKsl61898b40.sys [?]
S1 MpKsl9d6e38de;MpKsl9d6e38de;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{14e363de-8d35-4092-8fa7-36b468d1b59b}\mpksl9d6e38de.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{14e363de-8d35-4092-8fa7-36b468d1b59b}\MpKsl9d6e38de.sys [?]
S1 MpKslb3d1330b;MpKslb3d1330b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{10c69094-d2bc-468e-ad4e-b14fe1c5365f}\mpkslb3d1330b.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{10c69094-d2bc-468e-ad4e-b14fe1c5365f}\MpKslb3d1330b.sys [?]
S1 MpKslb5a07ffb;MpKslb5a07ffb;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\mpkslb5a07ffb.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\MpKslb5a07ffb.sys [?]
S1 MpKslb78b15a1;MpKslb78b15a1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{10c69094-d2bc-468e-ad4e-b14fe1c5365f}\mpkslb78b15a1.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{10c69094-d2bc-468e-ad4e-b14fe1c5365f}\MpKslb78b15a1.sys [?]
S1 MpKslc83e9ebf;MpKslc83e9ebf;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4539468b-f127-4e2f-b93b-79519c21b78a}\mpkslc83e9ebf.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4539468b-f127-4e2f-b93b-79519c21b78a}\MpKslc83e9ebf.sys [?]
S1 MpKsld1895537;MpKsld1895537;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\mpksld1895537.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{34f155d1-5841-4db3-bc99-1249c217698c}\MpKsld1895537.sys [?]
S1 MpKsle905f07a;MpKsle905f07a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dae9692b-afd7-461d-8a4f-21a708cd4fef}\mpksle905f07a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dae9692b-afd7-461d-8a4f-21a708cd4fef}\MpKsle905f07a.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 ThinkEco Modlet Service;ThinkEco Modlet Service;c:\program files\thinkeco\thinkeco.service.exe --> c:\program files\thinkeco\ThinkEco.Service.exe [?]
.
=============== Created Last 30 ================
.
2011-07-06 14:55:40 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\MpKsl9e2cf0b5.sys
2011-07-04 20:29:40 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\MpKslf32c8340.sys
2011-07-03 15:09:08 331776 ----a-w- c:\documents and settings\hp_administrator\local settings\application data\xra.exe
2011-07-03 05:54:28 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b7fb7c98-73e5-4e0f-9ac9-3a90193ac2f0}\mpengine.dll
2011-06-28 07:10:21 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-06-10 21:44:37 -------- d-----w- C:\ThinkEco
2011-06-10 21:44:37 -------- d-----w- c:\program files\common files\AppLifeUpdateService2
2011-06-10 21:44:30 -------- d-----w- c:\documents and settings\hp_administrator\application data\ThinkEco
2011-06-10 21:44:23 -------- d-----w- c:\documents and settings\all users\application data\ThinkEco
2011-06-10 21:33:49 73032 ----a-w- c:\windows\system32\drivers\ftser2k.sys
2011-06-10 21:33:49 67400 ----a-w- c:\windows\system32\ftcserco.dll
2011-06-10 21:33:49 52552 ----a-w- c:\windows\system32\ftserui2.dll
2011-06-10 21:33:46 60104 ----a-w- c:\windows\system32\drivers\ftdibus.sys
2011-06-10 21:33:46 198464 ----a-w- c:\windows\system32\ftd2xx.dll
2011-06-10 21:33:46 197952 ----a-w- c:\windows\system32\FTLang.dll
2011-06-10 21:33:46 105288 ----a-w- c:\windows\system32\ftbusui.dll
.
==================== Find3M ====================
.
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-29 14:57:06 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-04-29 14:57:05 410984 ----a-w- c:\windows\system32\deploytk.dll
2011-04-25 15:51:58 832512 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 15:51:57 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-04-25 15:51:57 1830912 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 15:51:57 17408 ----a-w- c:\windows\system32\corpol.dll
2011-04-25 12:01:21 389120 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
============= FINISH: 13:26:42.21 ===============
textbox. Do not include the word Code
.